Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36661 | WN08-00-000010-01 | SV-48278r1_rule | IAIA-1 | Medium |
Description |
---|
Application/service account passwords must be of sufficient length to prevent being easily cracked. Application/service accounts that are manually managed must have passwords at least 15 characters in length. |
STIG | Date |
---|---|
Windows 8 Security Technical Implementation Guide | 2014-01-07 |
Check Text ( C-44956r1_chk ) |
---|
The site must have a policy to ensure passwords for manually managed application/service accounts are at least 15 characters in length. If such a policy does not exist or has not been implemented, this is a finding. |
Fix Text (F-41413r1_fix) |
---|
Establish a site policy that defines the requirements for application/service account length. Create application/service account passwords that are at least 15 characters in length. |